<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: How to fix Leopard&#8217;s beef with firewalls</title>
	<atom:link href="http://www.crunchgear.com/2007/11/16/how-to-fix-leopards-beef-with-firewalls/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.crunchgear.com/2007/11/16/how-to-fix-leopards-beef-with-firewalls/</link>
	<description>Gadgets, gear and computer hardware.</description>
	<pubDate>Sun, 06 Jul 2008 21:48:42 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
		<item>
		<title>By: mindflux</title>
		<link>http://www.crunchgear.com/2007/11/16/how-to-fix-leopards-beef-with-firewalls/#comment-530352</link>
		<dc:creator>mindflux</dc:creator>
		<pubDate>Tue, 27 Nov 2007 03:05:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.crunchgear.com/2007/11/16/how-to-fix-leopards-beef-with-firewalls/#comment-530352</guid>
		<description>Does rule 900 ever get used?  It seems rule 600 will supersede it.

# If we let the conversation begin, let it continue
add 600 allow tcp from any to any established

# Block bogus inbounds that claim they were established
# add 900 deny log tcp from any to any established in</description>
		<content:encoded><![CDATA[<p>Does rule 900 ever get used?  It seems rule 600 will supersede it.</p>
<p># If we let the conversation begin, let it continue<br />
add 600 allow tcp from any to any established</p>
<p># Block bogus inbounds that claim they were established<br />
# add 900 deny log tcp from any to any established in</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sebhelyesfarku</title>
		<link>http://www.crunchgear.com/2007/11/16/how-to-fix-leopards-beef-with-firewalls/#comment-526280</link>
		<dc:creator>Sebhelyesfarku</dc:creator>
		<pubDate>Sat, 17 Nov 2007 14:25:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.crunchgear.com/2007/11/16/how-to-fix-leopards-beef-with-firewalls/#comment-526280</guid>
		<description>Fuck off James Lee</description>
		<content:encoded><![CDATA[<p>Fuck off James Lee</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: James Lee</title>
		<link>http://www.crunchgear.com/2007/11/16/how-to-fix-leopards-beef-with-firewalls/#comment-526152</link>
		<dc:creator>James Lee</dc:creator>
		<pubDate>Sat, 17 Nov 2007 08:10:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.crunchgear.com/2007/11/16/how-to-fix-leopards-beef-with-firewalls/#comment-526152</guid>
		<description>easy music downloads</description>
		<content:encoded><![CDATA[<p>easy music downloads</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Louis Wheeler</title>
		<link>http://www.crunchgear.com/2007/11/16/how-to-fix-leopards-beef-with-firewalls/#comment-525884</link>
		<dc:creator>Louis Wheeler</dc:creator>
		<pubDate>Fri, 16 Nov 2007 17:05:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.crunchgear.com/2007/11/16/how-to-fix-leopards-beef-with-firewalls/#comment-525884</guid>
		<description>Apple is trying something new; It is trying to make firewalls to be non-geeky. Naturally, the geeks resent that. But, Apple took away no functionality. The fans of ipfw can still use it. 

What the new firewall does is to keep the firewall off unless an application turns it on. Ipfw is port oriented while Apple's new system is application oriented. Most of Apple's customer would rather not mess with firewalls. Apple knows this and found a way to give them that.

Of course, Apple could have done a better job of explaining this.</description>
		<content:encoded><![CDATA[<p>Apple is trying something new; It is trying to make firewalls to be non-geeky. Naturally, the geeks resent that. But, Apple took away no functionality. The fans of ipfw can still use it. </p>
<p>What the new firewall does is to keep the firewall off unless an application turns it on. Ipfw is port oriented while Apple&#8217;s new system is application oriented. Most of Apple&#8217;s customer would rather not mess with firewalls. Apple knows this and found a way to give them that.</p>
<p>Of course, Apple could have done a better job of explaining this.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Greg</title>
		<link>http://www.crunchgear.com/2007/11/16/how-to-fix-leopards-beef-with-firewalls/#comment-525868</link>
		<dc:creator>Greg</dc:creator>
		<pubDate>Fri, 16 Nov 2007 16:10:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.crunchgear.com/2007/11/16/how-to-fix-leopards-beef-with-firewalls/#comment-525868</guid>
		<description>Well seems to be much more of a pro tip for sure. I can't say that I would like ipfw more then Apples new method. I think Ill get Apples new method a try seems to be pretty secure. However I guess you could augment it with Little Snitch.</description>
		<content:encoded><![CDATA[<p>Well seems to be much more of a pro tip for sure. I can&#8217;t say that I would like ipfw more then Apples new method. I think Ill get Apples new method a try seems to be pretty secure. However I guess you could augment it with Little Snitch.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chuck</title>
		<link>http://www.crunchgear.com/2007/11/16/how-to-fix-leopards-beef-with-firewalls/#comment-525862</link>
		<dc:creator>Chuck</dc:creator>
		<pubDate>Fri, 16 Nov 2007 15:23:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.crunchgear.com/2007/11/16/how-to-fix-leopards-beef-with-firewalls/#comment-525862</guid>
		<description>Wow, now I see why everyone sez Mac is so easy</description>
		<content:encoded><![CDATA[<p>Wow, now I see why everyone sez Mac is so easy</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.081 seconds -->
